About this role
<p style="margin:0.0in;line-height:normal;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="font-family:verdana, geneva, sans-serif;font-size:14.0pt;color:black"><strong>Job Title: Lead, Information Security Systems Engineering (ISSE)</strong></span></p> <p style="margin:0.0in;line-height:normal;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="font-family:verdana, geneva, sans-serif;font-size:14.0pt;color:black"><strong>Job Code: 40400</strong></span></p> <p style="margin:0.0in;line-height:normal;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="font-family:verdana, geneva, sans-serif;font-size:14.0pt;color:black"><strong>Job Location: Chantilly, VA</strong></span></p> <p style="margin:0.0in;line-height:normal;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="font-family:verdana, geneva, sans-serif;font-size:14.0pt;color:black"><strong>Job Schedule: 5/8 Monday - Friday</strong></span></p> <p style="margin:0.0in;line-height:normal;font-size:12.0pt;font-family:Aptos, sans-serif"><span style="font-family:verdana, geneva, sans-serif;font-size:14.0pt;color:black"><strong>Job Description:</strong></span></p> <p><span style="font-family:verdana, geneva, sans-serif;font-size:14.0pt;color:black">The successful candidate will support a highly motivated engineering team in defining, designing, implementing, documenting, testing and sustaining security solutions on National Security Systems, or other systems engineered for our government customers, using current standards within National Institute of Standards & Technology (NIST) Risk Management Framework, Special Publications 800-37, 800-53, 800-171, and other NIST publications; Committee on National Security Systems Instruction (CNNSI) 1253, Joint SAP Implementation Guide (JSIG), and Federal Information Processing Standards (FIPS) to certify and achieve system accreditations.</span></p> <p><span style="font-family:verdana, geneva, sans-serif;font-size:14.0pt;color:black">The successful candidate will work with system developers or commercial product vendors in the design and evaluation of state-of-the-art secure systems, networks, and database products, using methods such as encryption technology, vulnerability analysis and security management.</span></p> <p><span style="font-size:14.0pt;font-family:verdana, geneva, sans-serif;color:black"><strong>Essential Functions:</strong></span></p> <ul> <li style="font-family:verdana, geneva, sans-serif;font-size:14.0pt"><span style="font-family:verdana, geneva, sans-serif;font-size:14.0pt">Exercise skills in NIST Risk Management Framework (RMF) and all related NIST publications, to include writing System Security Plans, Security Control Traceability Matrix, Continuous Monitoring Plan, Security Assessment Plans & Procedures, Security Concept of Operations, Plan of Action and Milestones.</span></li> <li style="font-family:verdana, geneva, sans-serif;font-size:14.0pt"><span style="font-family:verdana, geneva, sans-serif;font-size:14.0pt">Perform skills in implementing/assessing security controls, to include writing system security categorization memorandum, recommending appropriate security control overlays, define security control baseline based on defined system security categorization and approved security overlays, and apply security controls to computing/network nodes and verify implementation of security controls.</span></li> <li style="font-family:verdana, geneva, sans-serif;font-size:14.0pt"><span style="font-family:verdana, geneva, sans-serif;font-size:14.0pt">Assist in systems/software engineering functions, to include creation of data flow diagrams, interface control documents, perform trade studies, and Static Application Security Testing (SAST) for Application Security and Development Secure Technical Implementation Guide (STIG) compliance using tools such as Fortify/Coverity and Gitlab as part of a DevSecOps Continuous Integration/Continuous Deployment (CI/CD) Pipeline, and generation of summary reports.</span></li> <li style="font-family:verdana, geneva, sans-serif;font-size:14.0pt"><span style="font-family:verdana, geneva, sans-serif;font-size:14.0pt">Define/manage systems/security architectures including cyber survivability attributes (including zero trust architecture), system security boundaries, vulnerability management and risk mitigation and remediation strategies within networks, systems, applications and new technology initiatives (hardware, software, firewalls, intrusion detection systems, anti-virus systems and software deployment tools); and Infrastructure/Platform/Software-as-a-Service (IaaS/PaaS/Saas) implementations in cloud environments.</span></li> <li style="font-family:verdana, geneva, sans-serif;font-size:14.0pt"><span style="font-family:verdana, geneva, sans-serif;font-size:14.0pt">This position is performed 100% onsite and cannot be performed remotely.</span></li> <li style="font-family:verdana, geneva, sans-serif;font-size:14.0pt"><span style="font-family:verdana, geneva, sans-serif;font-size:14.0pt">Up to 25% travel is possible</span></li> </ul> <p><span style="font-size:14.0pt;font-family:verdana, geneva, sans-serif;color:black"><strong>Qualifications: </strong> </span></p> <ul> <li style="font-family:verdana, geneva, sans-serif;font-size:14.0pt;color:black"><span style="font-family:verdana, geneva, sans-serif;font-size:14.0pt;color:black">Education</span> <ul> <li style="font-family:verdana, geneva, sans-serif;font-size:14.0pt;color:black"><span style="font-family:verdana, geneva, sans-serif;font-size:14.0pt;color:black">Bachelor’s Degree and minimum 9 years of prior relevant experience.</span></li> <li style="font-family:verdana, geneva, sans-serif;font-size:14.0pt;color:black"><span style="font-family:verdana, geneva, sans-serif;font-size:14.0pt;color:black">Graduate Degree and a minimum of 6 years of prior related experience.</span></li> <li style="font-family:verdana, geneva, sans-serif;font-size:14.0pt;color:black"><span style="font-family:verdana, geneva, sans-serif;font-size:14.0pt;color:black">In lieu of a degree, minimum of 12 years of prior related experience.</span></li> </ul> </li> <li style="font-family:verdana, geneva, sans-serif;font-size:14.0pt"><span style="font-family:verdana, geneva, sans-serif;font-size:14.0pt">Must have active TS/SCI clearance and willing to undergo a CI Polygraph. Active TS/SCI with poly is highly desired.</span></li> <li style="font-family:verdana, geneva, sans-serif;font-size:14.0pt"><span style="font-family:verdana, geneva, sans-serif;font-size:14.0pt">DoD 8140.03 IASAE Level 2 certification.</span></li> </ul> <p><span style="font-size:14.0pt;font-family:verdana, geneva, sans-serif;color:black"><strong>Preferred Additional Skills:</strong></span></p> <ul> <li style="font-family:verdana, geneva, sans-serif;font-size:14.0pt"><span style="font-family:verdana, geneva, sans-serif;font-size:14.0pt">Perform Model Based System Engineering (UML, SysML, UAF).</span></li> <li style="font-family:verdana, geneva, sans-serif;font-size:14.0pt"><span style="font-family:verdana, geneva, sans-serif;font-size:14.0pt">Confugure/operate vulnerability analysis tools such Tenable NESSUS Security products.</span></li> <li style="font-family:verdana, geneva, sans-serif;font-size:14.0pt"><span style="font-family:verdana, geneva, sans-serif;font-size:14.0pt">Develop dashboards, configure rules and operate/administer SEIM/audit reduction tools (e.g., Splunk).</span></li> </ul> <p><span style="font-family:verdana, geneva, sans-serif;font-size:14.0pt;color:black">In compliance with pay transparency requirements, the salary range for this role in California, Massachusetts, New Jersey, Washington, and the Greater D.C, Denver, or NYC areas is $127,500<em> - $236,500</em>. The salary range for this role in Colorado state, Hawaii, Illinois, Maryland, Minnesota, New York state, Cleveland Ohio, and Vermont is <em>$110,500 - $205,500</em>. This is not a guarantee of compensation or salary, as final offer amount may vary based on factors including but not limited to experience and geographic location. L3Harris also offers a variety of benefits, including health and disability insurance, 401(k) match, flexible spending accounts, EAP, education assistance, parental leave, paid time off, and company-paid holidays. The specific programs and options available to an employee may vary depending on date of hire, schedule type, and the applicability of collective bargaining agreements. </span></p> <p> </p>